Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3747

Опубликовано: 27 авг. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 7.5

Описание

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

РелизСтатусПримечание
dapper

ignored

end of life, was deferred
devel

not-affected

2.7.1-2ubuntu1
feisty

ignored

end of life, was deferred
gutsy

ignored

end of life, was deferred
hardy

ignored

end of life, was deferred
intrepid

ignored

end of life, was deferred
jaunty

not-affected

2.7.1-2ubuntu1
karmic

not-affected

2.7.1-2ubuntu1
lucid

not-affected

2.7.1-2ubuntu1
maverick

not-affected

2.7.1-2ubuntu1

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

nvd
около 17 лет назад

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

debian
около 17 лет назад

The (1) get_edit_post_link and (2) get_edit_comment_link functions in ...

github
больше 3 лет назад

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

7.5 High

CVSS2